Skip to content

Tabellio v0.5.0

Choose a tag to compare

@hudsonaikins hudsonaikins released this 23 Jul 18:15
· 25 commits to main since this release
c9759d7

Tabellio v0.5.0 is the first publication candidate after v0.2.0.

Versions 0.3.0 and 0.4.0 were development milestones. They were not tagged, released on GitHub, or published to npm. This release consolidates their capabilities with the validation hardening subsequently merged to main.

Highlights

  • Product-validity manifests bind acceptance outcomes, invariants, forbidden outcomes, risk, required validator types, metrics, artifacts, and cost telemetry to an exact candidate commit.
  • Required evidence ends as passed, failed, or blocked; missing proof and unknown required cost telemetry block readiness.
  • Release plans bind the exact merged commit, terminal review state, validation manifest, release notes, package version, and private control refs to a short-lived approval.
  • Pre-merge review gates require an open pull request and exact-head durable ready evidence; terminal state cannot be backfilled after merge.
  • Post-merge validation compares the landed commit with HEAD^, preserving exact-head proof after squash merges.
  • Validation workspaces, isolated homes, caches, and generated output live in private external temporary sessions.
  • Workspace containment and Git worktree cleanup fail closed before validation evidence can be published.
  • Preflight reads Codex hook-trust state directly. It never invokes the repair-oriented entire doctor command.

Publication Boundary

This document describes a release candidate. Publishing the annotated tag, private control refs, GitHub release, or npm package remains separately approval-gated. Pull-request merge also remains an explicit operator action.

Run all release gates on the exact merged main commit before authorizing publication.